{"cves":[{"id":"CVE-2009-0490","published":"2009-02-10T01:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in the String_parse::get_nonspace_quoted\nfunction in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other\nversions before 1.3.6 allows remote attackers to cause a denial of service\n(crash) and possibly execute arbitrary code via a .gro file containing a\nlong string.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0490"],"bugs":[""],"patches":{"audacity":[]},"tags":{},"packages":[{"name":"audacity","source":"https://ubuntu.com/security/cve?package=audacity","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audacity","debian":"https://tracker.debian.org/pkg/audacity","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.3.7-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.3.7-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.3.7-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.3.7-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.3.7-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.3.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0489","published":"2009-02-09T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe DBus configuration file for Wicd before 1.5.9 allows arbitrary users to\nown org.wicd.daemon, which allows local users to receive messages that were\nintended for the Wicd daemon, possibly including credentials.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0489"],"bugs":[""],"patches":{"wicd":[]},"tags":{},"packages":[{"name":"wicd","source":"https://ubuntu.com/security/cve?package=wicd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wicd","debian":"https://tracker.debian.org/pkg/wicd","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0487","published":"2009-02-09T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows\nremote attackers to inject arbitrary web script or HTML via a crafted forum\npost.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0487"],"bugs":[""],"patches":{"mahara":[]},"tags":{},"packages":[{"name":"mahara","source":"https://ubuntu.com/security/cve?package=mahara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mahara","debian":"https://tracker.debian.org/pkg/mahara","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.0.9-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.0.9-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6098","published":"2009-02-09T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20\nbefore 2.20.7, and other versions after 2.17.4 allows remote authenticated\nusers to bypass moderation to approve and disapprove quips via a direct\nrequest to quips.cgi with the action parameter set to \"approve.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6098"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.2.0.1-1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.0.1-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.0.1-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.0.1-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.0.1-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.0.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0486","published":"2009-02-09T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the\nsrand function at startup time, which causes Apache children to have the\nsame seed and produce insufficiently random numbers for random tokens,\nwhich allows remote attackers to bypass cross-site request forgery (CSRF)\nprotection mechanisms and conduct unauthorized activities as other users.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0486"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0485","published":"2009-02-09T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7,\n3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote\nattackers to delete unused flag types via a link or IMG tag to\neditflagtypes.cgi.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0485"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0484","published":"2009-02-09T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before\n3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to\ndelete shared or saved searches via a link or IMG tag to buglist.cgi.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0484"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0483","published":"2009-02-09T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before\n2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows\nremote attackers to delete keywords and user preferences via a link or IMG\ntag to (1) editkeywords.cgi or (2) userprefs.cgi.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0483"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0482","published":"2009-02-09T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2\nbefore 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote\nattackers to perform bug updating activities as other users via a link or\nIMG tag to process_bug.cgi.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0482"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0481","published":"2009-02-09T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3\nbefore 3.3.2 allows remote authenticated users to conduct cross-site\nscripting (XSS) and related attacks by uploading HTML and JavaScript\nattachments that are rendered by web browsers.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0481"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.2.4.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0502","published":"2009-02-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in blocks/html/block_html.php in\nSnoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8\nbefore 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject\narbitrary web script or HTML via an HTML block, which is not properly\nhandled when the \"Login as\" feature is used to visit a MyMoodle or Blog\npage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-791-1","https://www.cve.org/CVERecord?id=CVE-2009-0502"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.2-1.2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-791-1"],"notices":[{"id":"USN-791-1","title":"Moodle vulnerabilities","summary":"Moodle vulnerabilities","instructions":"After a standard system upgrade you need to access the Moodle instance\nand accept the database update to clear any invalid cached data.\n","references":[],"published":"2009-06-24T20:00:13.114186","description":"Thor Larholm discovered that PHPMailer, as used by Moodle, did not\ncorrectly escape email addresses. A local attacker with direct access\nto the Moodle database could exploit this to execute arbitrary commands\nas the web server user. (CVE-2007-3215)\n\nNigel McNie discovered that fetching https URLs did not correctly escape\nshell meta-characters. An authenticated remote attacker could execute\narbitrary commands as the web server user, if curl was installed and\nconfigured. (CVE-2008-4796, MSA-09-0003)\n\nIt was discovered that Smarty (also included in Moodle), did not\ncorrectly filter certain inputs. An authenticated remote attacker could\nexploit this to execute arbitrary PHP commands as the web server user.\n(CVE-2008-4810, CVE-2008-4811, CVE-2009-1669)\n\nIt was discovered that the unused SpellChecker extension in Moodle did not\ncorrectly handle temporary files. If the tool had been locally modified,\nit could be made to overwrite arbitrary local files via symlinks.\n(CVE-2008-5153)\n\nMike Churchward discovered that Moodle did not correctly filter Wiki page\ntitles in certain areas. An authenticated remote attacker could exploit\nthis to cause cross-site scripting (XSS), which could be used to modify\nor steal confidential data of other users within the same web domain.\n(CVE-2008-5432, MSA-08-0022)\n\nIt was discovered that the HTML sanitizer, \"Login as\" feature, and logging\nin Moodle did not correctly handle certain inputs. An authenticated\nremote attacker could exploit this to generate XSS, which could be used\nto modify or steal confidential data of other users within the same\nweb domain. (CVE-2008-5619, CVE-2009-0500, CVE-2009-0502, MSA-08-0026,\nMSA-09-0004, MSA-09-0007)\n\nIt was discovered that the HotPot module in Moodle did not correctly\nfilter SQL inputs. An authenticated remote attacker could execute\narbitrary SQL commands as the moodle database user, leading to a loss\nof privacy or denial of service. (CVE-2008-6124, MSA-08-0010)\n\nKevin Madura discovered that the forum actions and messaging settings\nin Moodle were not protected from cross-site request forgery (CSRF).\nIf an authenticated user were tricked into visiting a malicious\nwebsite while logged into Moodle, a remote attacker could change the\nuser's configurations or forum content. (CVE-2009-0499, MSA-09-0008,\nMSA-08-0023)\n\nDaniel Cabezas discovered that Moodle would leak usernames from the\nCalendar Export tool. A remote attacker could gather a list of users,\nleading to a loss of privacy. (CVE-2009-0501, MSA-09-0006)\n\nChristian Eibl discovered that the TeX filter in Moodle allowed any\nfunction to be used. An authenticated remote attacker could post\na specially crafted TeX formula to execute arbitrary TeX functions,\npotentially reading any file accessible to the web server user, leading\nto a loss of privacy. (CVE-2009-1171, MSA-09-0009)\n\nJohannes Kuhn discovered that Moodle did not correctly validate user\npermissions when attempting to switch user accounts. An authenticated\nremote attacker could switch to any other Moodle user, leading to a loss\nof privacy. (MSA-08-0003)\n\nHanno Boeck discovered that unconfigured Moodle instances contained\nXSS vulnerabilities. An unauthenticated remote attacker could exploit\nthis to modify or steal confidential data of other users within the same\nweb domain. (MSA-08-0004)\n\nDebbie McDonald, Mauno Korpelainen, Howard Miller, and Juan Segarra\nMontesinos discovered that when users were deleted from Moodle, their\nprofiles and avatars were still visible. An authenticated remote attacker\ncould exploit this to store information in profiles even after they were\nremoved, leading to spam traffic. (MSA-08-0015, MSA-09-0001, MSA-09-0002)\n\nLars Vogdt discovered that Moodle did not correctly filter certain inputs.\nAn authenticated remote attacker could exploit this to generate XSS from\nwhich they could modify or steal confidential data of other users within\nthe same web domain. (MSA-08-0021)\n\nIt was discovered that Moodle did not correctly filter inputs for group\ncreation, mnet, essay question, HOST param, wiki param, and others.\nAn authenticated remote attacker could exploit this to generate XSS\nfrom which they could modify or steal confidential data of other users\nwithin the same web domain. (MDL-9288, MDL-11759, MDL-12079, MDL-12793,\nMDL-14806)\n\nIt was discovered that Moodle did not correctly filter SQL inputs when\nperforming a restore. An attacker authenticated as a Moodle administrator\ncould execute arbitrary SQL commands as the moodle database user,\nleading to a loss of privacy or denial of service. (MDL-11857)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moodle","version":"1.8.2-1ubuntu4.2","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1ubuntu4.2"}],"intrepid":[{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1.2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-0500","CVE-2007-3215","CVE-2008-5619","CVE-2009-0502","CVE-2008-5432","CVE-2008-5153","CVE-2009-0499","CVE-2008-4810","CVE-2009-0501","CVE-2008-6124","CVE-2008-4796","CVE-2008-4811","CVE-2009-1171","CVE-2009-1669"]}]},{"id":"CVE-2009-0501","published":"2009-02-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Calendar export feature in Moodle 1.8\nbefore 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive\ninformation and conduct \"brute force attacks on user accounts\" via unknown\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-791-1","https://www.cve.org/CVERecord?id=CVE-2009-0501"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.2-1.2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-791-1"],"notices":[{"id":"USN-791-1","title":"Moodle vulnerabilities","summary":"Moodle vulnerabilities","instructions":"After a standard system upgrade you need to access the Moodle instance\nand accept the database update to clear any invalid cached data.\n","references":[],"published":"2009-06-24T20:00:13.114186","description":"Thor Larholm discovered that PHPMailer, as used by Moodle, did not\ncorrectly escape email addresses. A local attacker with direct access\nto the Moodle database could exploit this to execute arbitrary commands\nas the web server user. (CVE-2007-3215)\n\nNigel McNie discovered that fetching https URLs did not correctly escape\nshell meta-characters. An authenticated remote attacker could execute\narbitrary commands as the web server user, if curl was installed and\nconfigured. (CVE-2008-4796, MSA-09-0003)\n\nIt was discovered that Smarty (also included in Moodle), did not\ncorrectly filter certain inputs. An authenticated remote attacker could\nexploit this to execute arbitrary PHP commands as the web server user.\n(CVE-2008-4810, CVE-2008-4811, CVE-2009-1669)\n\nIt was discovered that the unused SpellChecker extension in Moodle did not\ncorrectly handle temporary files. If the tool had been locally modified,\nit could be made to overwrite arbitrary local files via symlinks.\n(CVE-2008-5153)\n\nMike Churchward discovered that Moodle did not correctly filter Wiki page\ntitles in certain areas. An authenticated remote attacker could exploit\nthis to cause cross-site scripting (XSS), which could be used to modify\nor steal confidential data of other users within the same web domain.\n(CVE-2008-5432, MSA-08-0022)\n\nIt was discovered that the HTML sanitizer, \"Login as\" feature, and logging\nin Moodle did not correctly handle certain inputs. An authenticated\nremote attacker could exploit this to generate XSS, which could be used\nto modify or steal confidential data of other users within the same\nweb domain. (CVE-2008-5619, CVE-2009-0500, CVE-2009-0502, MSA-08-0026,\nMSA-09-0004, MSA-09-0007)\n\nIt was discovered that the HotPot module in Moodle did not correctly\nfilter SQL inputs. An authenticated remote attacker could execute\narbitrary SQL commands as the moodle database user, leading to a loss\nof privacy or denial of service. (CVE-2008-6124, MSA-08-0010)\n\nKevin Madura discovered that the forum actions and messaging settings\nin Moodle were not protected from cross-site request forgery (CSRF).\nIf an authenticated user were tricked into visiting a malicious\nwebsite while logged into Moodle, a remote attacker could change the\nuser's configurations or forum content. (CVE-2009-0499, MSA-09-0008,\nMSA-08-0023)\n\nDaniel Cabezas discovered that Moodle would leak usernames from the\nCalendar Export tool. A remote attacker could gather a list of users,\nleading to a loss of privacy. (CVE-2009-0501, MSA-09-0006)\n\nChristian Eibl discovered that the TeX filter in Moodle allowed any\nfunction to be used. An authenticated remote attacker could post\na specially crafted TeX formula to execute arbitrary TeX functions,\npotentially reading any file accessible to the web server user, leading\nto a loss of privacy. (CVE-2009-1171, MSA-09-0009)\n\nJohannes Kuhn discovered that Moodle did not correctly validate user\npermissions when attempting to switch user accounts. An authenticated\nremote attacker could switch to any other Moodle user, leading to a loss\nof privacy. (MSA-08-0003)\n\nHanno Boeck discovered that unconfigured Moodle instances contained\nXSS vulnerabilities. An unauthenticated remote attacker could exploit\nthis to modify or steal confidential data of other users within the same\nweb domain. (MSA-08-0004)\n\nDebbie McDonald, Mauno Korpelainen, Howard Miller, and Juan Segarra\nMontesinos discovered that when users were deleted from Moodle, their\nprofiles and avatars were still visible. An authenticated remote attacker\ncould exploit this to store information in profiles even after they were\nremoved, leading to spam traffic. (MSA-08-0015, MSA-09-0001, MSA-09-0002)\n\nLars Vogdt discovered that Moodle did not correctly filter certain inputs.\nAn authenticated remote attacker could exploit this to generate XSS from\nwhich they could modify or steal confidential data of other users within\nthe same web domain. (MSA-08-0021)\n\nIt was discovered that Moodle did not correctly filter inputs for group\ncreation, mnet, essay question, HOST param, wiki param, and others.\nAn authenticated remote attacker could exploit this to generate XSS\nfrom which they could modify or steal confidential data of other users\nwithin the same web domain. (MDL-9288, MDL-11759, MDL-12079, MDL-12793,\nMDL-14806)\n\nIt was discovered that Moodle did not correctly filter SQL inputs when\nperforming a restore. An attacker authenticated as a Moodle administrator\ncould execute arbitrary SQL commands as the moodle database user,\nleading to a loss of privacy or denial of service. (MDL-11857)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moodle","version":"1.8.2-1ubuntu4.2","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1ubuntu4.2"}],"intrepid":[{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1.2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-0500","CVE-2007-3215","CVE-2008-5619","CVE-2009-0502","CVE-2008-5432","CVE-2008-5153","CVE-2009-0499","CVE-2008-4810","CVE-2009-0501","CVE-2008-6124","CVE-2008-4796","CVE-2008-4811","CVE-2009-1171","CVE-2009-1669"]}]},{"id":"CVE-2009-0500","published":"2009-02-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6\nbefore 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4\nallows remote attackers to inject arbitrary web script or HTML via crafted\nlog table information that is not properly handled when it is displayed in\na log report.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-791-1","https://www.cve.org/CVERecord?id=CVE-2009-0500"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.2-1.2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-791-1"],"notices":[{"id":"USN-791-1","title":"Moodle vulnerabilities","summary":"Moodle vulnerabilities","instructions":"After a standard system upgrade you need to access the Moodle instance\nand accept the database update to clear any invalid cached data.\n","references":[],"published":"2009-06-24T20:00:13.114186","description":"Thor Larholm discovered that PHPMailer, as used by Moodle, did not\ncorrectly escape email addresses. A local attacker with direct access\nto the Moodle database could exploit this to execute arbitrary commands\nas the web server user. (CVE-2007-3215)\n\nNigel McNie discovered that fetching https URLs did not correctly escape\nshell meta-characters. An authenticated remote attacker could execute\narbitrary commands as the web server user, if curl was installed and\nconfigured. (CVE-2008-4796, MSA-09-0003)\n\nIt was discovered that Smarty (also included in Moodle), did not\ncorrectly filter certain inputs. An authenticated remote attacker could\nexploit this to execute arbitrary PHP commands as the web server user.\n(CVE-2008-4810, CVE-2008-4811, CVE-2009-1669)\n\nIt was discovered that the unused SpellChecker extension in Moodle did not\ncorrectly handle temporary files. If the tool had been locally modified,\nit could be made to overwrite arbitrary local files via symlinks.\n(CVE-2008-5153)\n\nMike Churchward discovered that Moodle did not correctly filter Wiki page\ntitles in certain areas. An authenticated remote attacker could exploit\nthis to cause cross-site scripting (XSS), which could be used to modify\nor steal confidential data of other users within the same web domain.\n(CVE-2008-5432, MSA-08-0022)\n\nIt was discovered that the HTML sanitizer, \"Login as\" feature, and logging\nin Moodle did not correctly handle certain inputs. An authenticated\nremote attacker could exploit this to generate XSS, which could be used\nto modify or steal confidential data of other users within the same\nweb domain. (CVE-2008-5619, CVE-2009-0500, CVE-2009-0502, MSA-08-0026,\nMSA-09-0004, MSA-09-0007)\n\nIt was discovered that the HotPot module in Moodle did not correctly\nfilter SQL inputs. An authenticated remote attacker could execute\narbitrary SQL commands as the moodle database user, leading to a loss\nof privacy or denial of service. (CVE-2008-6124, MSA-08-0010)\n\nKevin Madura discovered that the forum actions and messaging settings\nin Moodle were not protected from cross-site request forgery (CSRF).\nIf an authenticated user were tricked into visiting a malicious\nwebsite while logged into Moodle, a remote attacker could change the\nuser's configurations or forum content. (CVE-2009-0499, MSA-09-0008,\nMSA-08-0023)\n\nDaniel Cabezas discovered that Moodle would leak usernames from the\nCalendar Export tool. A remote attacker could gather a list of users,\nleading to a loss of privacy. (CVE-2009-0501, MSA-09-0006)\n\nChristian Eibl discovered that the TeX filter in Moodle allowed any\nfunction to be used. An authenticated remote attacker could post\na specially crafted TeX formula to execute arbitrary TeX functions,\npotentially reading any file accessible to the web server user, leading\nto a loss of privacy. (CVE-2009-1171, MSA-09-0009)\n\nJohannes Kuhn discovered that Moodle did not correctly validate user\npermissions when attempting to switch user accounts. An authenticated\nremote attacker could switch to any other Moodle user, leading to a loss\nof privacy. (MSA-08-0003)\n\nHanno Boeck discovered that unconfigured Moodle instances contained\nXSS vulnerabilities. An unauthenticated remote attacker could exploit\nthis to modify or steal confidential data of other users within the same\nweb domain. (MSA-08-0004)\n\nDebbie McDonald, Mauno Korpelainen, Howard Miller, and Juan Segarra\nMontesinos discovered that when users were deleted from Moodle, their\nprofiles and avatars were still visible. An authenticated remote attacker\ncould exploit this to store information in profiles even after they were\nremoved, leading to spam traffic. (MSA-08-0015, MSA-09-0001, MSA-09-0002)\n\nLars Vogdt discovered that Moodle did not correctly filter certain inputs.\nAn authenticated remote attacker could exploit this to generate XSS from\nwhich they could modify or steal confidential data of other users within\nthe same web domain. (MSA-08-0021)\n\nIt was discovered that Moodle did not correctly filter inputs for group\ncreation, mnet, essay question, HOST param, wiki param, and others.\nAn authenticated remote attacker could exploit this to generate XSS\nfrom which they could modify or steal confidential data of other users\nwithin the same web domain. (MDL-9288, MDL-11759, MDL-12079, MDL-12793,\nMDL-14806)\n\nIt was discovered that Moodle did not correctly filter SQL inputs when\nperforming a restore. An attacker authenticated as a Moodle administrator\ncould execute arbitrary SQL commands as the moodle database user,\nleading to a loss of privacy or denial of service. (MDL-11857)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moodle","version":"1.8.2-1ubuntu4.2","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1ubuntu4.2"}],"intrepid":[{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1.2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-0500","CVE-2007-3215","CVE-2008-5619","CVE-2009-0502","CVE-2008-5432","CVE-2008-5153","CVE-2009-0499","CVE-2008-4810","CVE-2009-0501","CVE-2008-6124","CVE-2008-4796","CVE-2008-4811","CVE-2009-1171","CVE-2009-1669"]}]},{"id":"CVE-2009-0499","published":"2009-02-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in the forum code in Moodle\n1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote\nattackers to delete unauthorized forum posts via a link or IMG tag to\npost.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-791-1","https://www.cve.org/CVERecord?id=CVE-2009-0499"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.8.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.8.2-1.2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.9.4.dfsg-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-791-1"],"notices":[{"id":"USN-791-1","title":"Moodle vulnerabilities","summary":"Moodle vulnerabilities","instructions":"After a standard system upgrade you need to access the Moodle instance\nand accept the database update to clear any invalid cached data.\n","references":[],"published":"2009-06-24T20:00:13.114186","description":"Thor Larholm discovered that PHPMailer, as used by Moodle, did not\ncorrectly escape email addresses. A local attacker with direct access\nto the Moodle database could exploit this to execute arbitrary commands\nas the web server user. (CVE-2007-3215)\n\nNigel McNie discovered that fetching https URLs did not correctly escape\nshell meta-characters. An authenticated remote attacker could execute\narbitrary commands as the web server user, if curl was installed and\nconfigured. (CVE-2008-4796, MSA-09-0003)\n\nIt was discovered that Smarty (also included in Moodle), did not\ncorrectly filter certain inputs. An authenticated remote attacker could\nexploit this to execute arbitrary PHP commands as the web server user.\n(CVE-2008-4810, CVE-2008-4811, CVE-2009-1669)\n\nIt was discovered that the unused SpellChecker extension in Moodle did not\ncorrectly handle temporary files. If the tool had been locally modified,\nit could be made to overwrite arbitrary local files via symlinks.\n(CVE-2008-5153)\n\nMike Churchward discovered that Moodle did not correctly filter Wiki page\ntitles in certain areas. An authenticated remote attacker could exploit\nthis to cause cross-site scripting (XSS), which could be used to modify\nor steal confidential data of other users within the same web domain.\n(CVE-2008-5432, MSA-08-0022)\n\nIt was discovered that the HTML sanitizer, \"Login as\" feature, and logging\nin Moodle did not correctly handle certain inputs. An authenticated\nremote attacker could exploit this to generate XSS, which could be used\nto modify or steal confidential data of other users within the same\nweb domain. (CVE-2008-5619, CVE-2009-0500, CVE-2009-0502, MSA-08-0026,\nMSA-09-0004, MSA-09-0007)\n\nIt was discovered that the HotPot module in Moodle did not correctly\nfilter SQL inputs. An authenticated remote attacker could execute\narbitrary SQL commands as the moodle database user, leading to a loss\nof privacy or denial of service. (CVE-2008-6124, MSA-08-0010)\n\nKevin Madura discovered that the forum actions and messaging settings\nin Moodle were not protected from cross-site request forgery (CSRF).\nIf an authenticated user were tricked into visiting a malicious\nwebsite while logged into Moodle, a remote attacker could change the\nuser's configurations or forum content. (CVE-2009-0499, MSA-09-0008,\nMSA-08-0023)\n\nDaniel Cabezas discovered that Moodle would leak usernames from the\nCalendar Export tool. A remote attacker could gather a list of users,\nleading to a loss of privacy. (CVE-2009-0501, MSA-09-0006)\n\nChristian Eibl discovered that the TeX filter in Moodle allowed any\nfunction to be used. An authenticated remote attacker could post\na specially crafted TeX formula to execute arbitrary TeX functions,\npotentially reading any file accessible to the web server user, leading\nto a loss of privacy. (CVE-2009-1171, MSA-09-0009)\n\nJohannes Kuhn discovered that Moodle did not correctly validate user\npermissions when attempting to switch user accounts. An authenticated\nremote attacker could switch to any other Moodle user, leading to a loss\nof privacy. (MSA-08-0003)\n\nHanno Boeck discovered that unconfigured Moodle instances contained\nXSS vulnerabilities. An unauthenticated remote attacker could exploit\nthis to modify or steal confidential data of other users within the same\nweb domain. (MSA-08-0004)\n\nDebbie McDonald, Mauno Korpelainen, Howard Miller, and Juan Segarra\nMontesinos discovered that when users were deleted from Moodle, their\nprofiles and avatars were still visible. An authenticated remote attacker\ncould exploit this to store information in profiles even after they were\nremoved, leading to spam traffic. (MSA-08-0015, MSA-09-0001, MSA-09-0002)\n\nLars Vogdt discovered that Moodle did not correctly filter certain inputs.\nAn authenticated remote attacker could exploit this to generate XSS from\nwhich they could modify or steal confidential data of other users within\nthe same web domain. (MSA-08-0021)\n\nIt was discovered that Moodle did not correctly filter inputs for group\ncreation, mnet, essay question, HOST param, wiki param, and others.\nAn authenticated remote attacker could exploit this to generate XSS\nfrom which they could modify or steal confidential data of other users\nwithin the same web domain. (MDL-9288, MDL-11759, MDL-12079, MDL-12793,\nMDL-14806)\n\nIt was discovered that Moodle did not correctly filter SQL inputs when\nperforming a restore. An attacker authenticated as a Moodle administrator\ncould execute arbitrary SQL commands as the moodle database user,\nleading to a loss of privacy or denial of service. (MDL-11857)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"moodle","version":"1.8.2-1ubuntu4.2","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1ubuntu4.2"}],"intrepid":[{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","description":"","is_source":true},{"name":"moodle","version":"1.8.2-1.2ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/moodle","version_link":"https://launchpad.net/ubuntu/+source/moodle/1.8.2-1.2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-0500","CVE-2007-3215","CVE-2008-5619","CVE-2009-0502","CVE-2008-5432","CVE-2008-5153","CVE-2009-0499","CVE-2008-4810","CVE-2009-0501","CVE-2008-6124","CVE-2008-4796","CVE-2008-4811","CVE-2009-1171","CVE-2009-1669"]}]},{"id":"CVE-2009-0478","published":"2009-02-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSquid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows\nremote attackers to cause a denial of service via an HTTP request with an\ninvalid version number, which triggers a reachable assertion in (1)\nHttpMsg.c and (2) HttpStatusLine.c.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"2.6 and lower not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-724-1","https://www.cve.org/CVERecord?id=CVE-2009-0478"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/squid3/+bug/330192"],"patches":{"squid":[],"squid3":[]},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.7.STABLE3-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"2.7.STABLE3-4.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"2.7.STABLE3-4.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.7.STABLE3-4.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"2.7.STABLE3-4.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.7.STABLE3-4.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.7.STABLE3-4.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.STABLE3-4.1ubuntu1","component":null,"pocket":"security"}]},{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"3.0.STABLE8-3","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"3.0.STABLE8-3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.0.STABLE8-3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.0.STABLE8-3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.0.STABLE8-3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.0.STABLE8-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.STABLE8-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-724-1"],"notices":[{"id":"USN-724-1","title":"Squid vulnerability","summary":"Squid vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-02-25T21:17:00.553857","description":"Joshua Morin, Mikko Varpiola and Jukka Taimisto discovered that Squid did\nnot properly validate the HTTP version when processing requests. A remote\nattacker could exploit this to cause a denial of service (assertion failure).\n","is_hidden":false,"release_packages":{"intrepid":[{"name":"squid","version":"2.7.STABLE3-1ubuntu2.1","description":"","is_source":true},{"name":"squid","version":"2.7.STABLE3-1ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/2.7.STABLE3-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2009-0478"]}]},{"id":"CVE-2008-6079","published":"2009-02-06T11:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nimlib2 before 1.4.2 allows context-dependent attackers to have an\nunspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5)\nPNM, (6) TGA, or (7) XPM file, related to \"several heap and stack based\nbuffer overflows - partly due to integer overflows.\"","ubuntu_description":"","notes":[{"author":"kees","note":"no details on the flaws yet."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6079"],"bugs":[""],"patches":{"imlib2":[]},"tags":{},"packages":[{"name":"imlib2","source":"https://ubuntu.com/security/cve?package=imlib2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imlib2","debian":"https://tracker.debian.org/pkg/imlib2","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"1.4.2-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"1.4.2-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.4.2-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.4.2-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.4.2-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-6059","published":"2009-02-05T00:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nxml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly\nrestrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2\nHTTP response headers, which allows remote attackers to obtain sensitive\ninformation from cookies via XMLHttpRequest calls, related to the HTTPOnly\nprotection mechanism.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"may not be vulnerable, see debian bug\nupstream patch is mac and win only. version of webkit in linux\nneeds libsoup for cookie support."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-6059"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=516555","https://bugs.webkit.org/show_bug.cgi?id=10957","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-6059"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/38566"]},"tags":{},"packages":[{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0388","published":"2009-02-04T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2)\nTightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap\ncorruption and application crash) or possibly execute arbitrary code via a\nlarge length value in a message, related to the (a)\nClientConnection::CheckBufferSize and (b)\nClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"windows only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.coresecurity.com/content/vnc-integer-overflows","https://www.cve.org/CVERecord?id=CVE-2009-0388"],"bugs":[""],"patches":{"tightvnc":["upstream: http://vnc-tight.svn.sourceforge.net/viewvc/vnc-tight?view=rev&revision=3564"]},"tags":{},"packages":[{"name":"tightvnc","source":"https://ubuntu.com/security/cve?package=tightvnc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tightvnc","debian":"https://tracker.debian.org/pkg/tightvnc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-0358","published":"2009-02-04T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox 3.x before 3.0.6 does not properly implement the (1)\nno-store and (2) no-cache Cache-Control directives, which allows local\nusers to obtain sensitive information by using the (a) back button or (b)\nhistory list of the victim's browser, as demonstrated by reading the\nresponse page of an https POST request.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-717-1","https://www.cve.org/CVERecord?id=CVE-2009-0358"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"iceweasel":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"3.0.6+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.6","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"iceweasel","source":"https://ubuntu.com/security/cve?package=iceweasel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceweasel","debian":"https://tracker.debian.org/pkg/iceweasel","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.0.6+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.9.0.6+nobinonly-0ubuntu0.8.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.06","component":null,"pocket":"security"}]}],"notices_ids":["USN-717-1"],"notices":[{"id":"USN-717-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox and Xulrunner vulnerabilities","instructions":"After a standard system upgrade you need to restart Firefox and any\napplications that use xulrunner, such as Epiphany, to effect the necessary\nchanges.\n","references":[],"published":"2009-02-10T23:13:16.566010","description":"Several flaws were discovered in the browser engine. These problems could allow\nan attacker to crash the browser and possibly execute arbitrary code with user\nprivileges. (CVE-2009-0352, CVE-2009-0353)\n\nA flaw was discovered in the JavaScript engine. An attacker could bypass the\nsame-origin policy in Firefox by utilizing a chrome XBL method and execute\narbitrary JavaScript within the context of another website. (CVE-2009-0354)\n\nA flaw was discovered in the browser engine when restoring closed tabs. If a\nuser were tricked into restoring a tab to a malicious website with form input\ncontrols, an attacker could steal local files on the user's system.\n(CVE-2009-0355)\n\nWladimir Palant discovered that Firefox did not restrict access to cookies in\nHTTP response headers. If a user were tricked into opening a malicious web\npage, a remote attacker could view sensitive information. (CVE-2009-0357)\n\nPaul Nel discovered that Firefox did not honor certain Cache-Control HTTP\ndirectives. A local attacker could exploit this to view private data in\nimproperly cached pages of another user. (CVE-2009-0358)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.0.6+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.6+nobinonly-0ubuntu0.8.04.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.6+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9","version":"1.9.0.6+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.6+nobinonly-0ubuntu0.8.04.1"}],"intrepid":[{"name":"firefox-3.0","version":"3.0.6+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"xulrunner-1.9","version":"1.9.0.6+nobinonly-0ubuntu0.8.10.1","description":"","is_source":true},{"name":"firefox-3.0","version":"3.0.6+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.6+nobinonly-0ubuntu0.8.10.1"},{"name":"abrowser","version":"3.0.6+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.0.6+nobinonly-0ubuntu0.8.10.1"},{"name":"xulrunner-1.9","version":"1.9.0.6+nobinonly-0ubuntu0.8.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9/1.9.0.6+nobinonly-0ubuntu0.8.10.1"}]},"type":"USN","cves_ids":["CVE-2009-0352","CVE-2009-0353","CVE-2009-0354","CVE-2009-0355","CVE-2009-0357","CVE-2009-0358"]}]},{"id":"CVE-2009-0356","published":"2009-02-04T19:30:00","updated_at":"2025-08-04T19:23:31.266285+00:00","description":"\nMozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1)\nabout:plugins and (2) about:config URIs from .desktop files, which allows\nuser-assisted remote attackers to bypass the Same Origin Policy and execute\narbitrary code with chrome privileges via vectors involving the URL field\nin a Desktop Entry section of a .desktop file, related to representation of\nabout: URIs as jar:file:// URIs. NOTE: this issue exists because of an\nincomplete fix for CVE-2008-4582.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"not a linux issue per asac"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-0356"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"iceweasel":[],"xulrunner":[],"xulrunner-1.9":[],"seamonkey":[],"iceape":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.6","component":null,"pocket":"security"}]},{"name":"iceape","source":"https://ubuntu.com/security/cve?package=iceape","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceape","debian":"https://tracker.debian.org/pkg/iceape","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"iceweasel","source":"https://ubuntu.com/security/cve?package=iceweasel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iceweasel","debian":"https://tracker.debian.org/pkg/iceweasel","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner","source":"https://ubuntu.com/security/cve?package=xulrunner","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner","debian":"https://tracker.debian.org/pkg/xulrunner","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9","debian":"https://tracker.debian.org/pkg/xulrunner-1.9","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"gutsy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":74420,"limit":20,"total_results":79316}